SuperBond

Privacy Policy

Last updated [[ DATE ]]

⚠️ This is a scaffold, not a finished policy. Every [[ HIGHLIGHTED ]] item needs a real answer, and the sections marked Needs counsel involve decisions a lawyer should make. The factual descriptions below were written from the app's actual behaviour and should be accurate — but accuracy about what the code does is not the same as legal sufficiency. Do not publish this page while this box is still on it.

SuperBond is a dating app operated by [[ LEGAL ENTITY NAME ]] (“we”, “us”). This policy explains what we collect, why, who we share it with, and what you can do about it. If you have questions, contact us at [[ PRIVACY CONTACT EMAIL ]].

Who this policy is for

SuperBond is for adults. You must be 18 or older to create an account, and we ask for your date of birth during sign-up to enforce that. We do not knowingly collect information from anyone under 18.

What we collect

Some of this is required to make the app work at all; some is optional and marked so.

WhatWhyRequired?
Email addressFrom Google or Apple sign-in, to identify your accountYes
Date of birthTo confirm you are 18+ and show your ageYes
First name and a separate Discussion handleYour name appears on your profile; the handle is what the community board shows insteadYes
Photos (3–5)Your profileYes
Approximate locationTo show people near you and to decide when SuperBond opens in your areaYes
Gender, who you are open to dating, relationship typeMatchingYes
Sexual orientationShown on your profile only if you switch it onNo
About You details (height, kids, smoking, drinking, bio)Your profileNo
A selfie, if you ask to be verifiedTo confirm you are the person in your photosNo
Messages, discussion posts and votesTo deliver themYes, if you use those features
Device identifier and notification tokenTo send notifications and to enforce bansYes
Purchase recordsTo give you what you paid forYes, if you subscribe

Location: what we actually store

We store the centre of your city, not your position. If you use “Use my current location”, your device works out where you are, the app picks the nearest city from a fixed list, and the precise reading is discarded and never sent to us. On Android the app only ever asks for approximate location; on iOS it asks for reduced accuracy. Distances shown to other members are rounded and never displayed below one mile.

Sexual orientation

This is optional, and answering it is separate from publishing it. It is hidden unless you turn on the visibility switch, and if you clear your answer the permission to show it is cleared too.

Needs counsel — special category data. Sexual orientation is special category data under UK/EU GDPR (Art. 9) and sensitive personal information under the CPRA. The lawful basis is most likely explicit consent, which affects how the switch must be worded and recorded.

Verification selfies and face comparison

If you ask to be verified, we compare your selfie with your profile photos. That comparison is performed by Amazon Rekognition, an automated face-comparison service, and the result is reviewed by a member of our team. The automated check can confirm a match; it never rejects anyone on its own. Your selfie is deleted as soon as the review is finished and is never shown on your profile or to other members.

Needs counsel — biometric identifiers. Automated face comparison creates a scan of face geometry, which is regulated specifically by the Illinois Biometric Information Privacy Act, Texas CUBI and Washington's My Health My Data Act, among others. These typically require informed written consent before collection and a published retention and destruction schedule. Confirm: the consent wording, whether to offer verification at all in those states, and the retention statement. Note the automated check is currently in an advisory mode where a person still decides, but images are sent to AWS either way.

How we use it

We do not sell your personal information for money. Showing personalised ads may count as “sharing” under California law — see Your choices.

Who we share it with

ServiceWhat they receiveWhy
SupabaseYour account, profile, photos and messagesHosting, database and file storage
Amazon Web Services (Rekognition)Your selfie and profile photos, only if you request verificationAutomated face comparison
Google FirebaseA notification token for your devicePush notifications
Google AdMobAd request dataAds for free-tier members
PostHogProduct analytics, linked to your accountUnderstanding how the app is used
SentryCrash reports, with your account identifier onlyDiagnosing crashes
Apple and GooglePurchase and subscription recordsProcessing payments

Other members see your profile, your photos, and anything you post or send.

Needs counsel — international transfers and processor terms. Confirm where each processor stores data, whether transfer mechanisms (SCCs or equivalent) are needed, and that data processing agreements are in place. [[ Also confirm the app is US-only at launch, or list the regions ]]

Your choices

How long we keep it

Verification selfies are deleted as soon as a review is complete. [[ RETENTION PERIODS for accounts, deleted accounts, messages, moderation records and device bans ]]

Needs counsel — retention. Moderation records and device-ban records are deliberately kept after an account is gone, because they are what stops a banned person returning. That needs a stated basis and a period.

Your rights

Depending on where you live, you may have the right to access, correct, delete or export your information, to object to certain processing, and to withdraw consent. Contact [[ PRIVACY CONTACT EMAIL ]] and we will respond within [[ STATUTORY PERIOD ]].

Needs counsel — jurisdiction-specific sections. GDPR requires a stated legal basis per purpose, controller identity and address, and a supervisory-authority complaint route. The CPRA requires categories of personal information collected, disclosed and shared, plus a “Notice at Collection”. Both stores' listing metadata must match whatever this page says.

Security

Profile photos and verification selfies are stored in private buckets that are not publicly readable; access is granted per request and expires. Verification selfies are readable only by our moderation team, and every time a moderator views one it is recorded.

Changes

If we change this policy we will update the date at the top, and tell you in the app if the change is significant.